Skip to content

privacy

Privacy Policy

Last updated: 29 August 2026 1. Data protection at a glance General information The protection of your personal data is important to us. This Privacy Policy explains which personal data is processed when you use our website, for what purposes, on what legal basis such processing takes place, and what rights you have under applicable data protection law. Personal data means any information relating to an identified or identifiable natural person. This may include, in particular, your name, email address, telephone number, postal address, payment details, IP address, and technical usage data. Data controller The controller responsible for the processing of personal data on this website is: Predator SLU Carrer Vicari Joaquin Fuster, 31 07006 Palma, Illes Balears Spain Telephone: +34 871 180 796 Email: info@predatorsl.com The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data. 2. Legal bases for data processing We process personal data only where there is a legal basis for doing so. Depending on the type of processing, the following legal bases under the General Data Protection Regulation (GDPR) apply in particular: • Art. 6(1)(a) GDPR – Consent: where you have expressly consented to specific processing, for example the use of non-essential analytics technologies. • Art. 6(1)(b) GDPR – Contract and pre-contractual measures: where processing is necessary for the performance of a contract or to respond to a request before entering into a contract. • Art. 6(1)(c) GDPR – Legal obligation: where we are required to process personal data in order to comply with legal obligations, for example commercial, tax, or payment-related obligations. • Art. 6(1)(f) GDPR – Legitimate interests: where processing is necessary to protect our legitimate interests or those of a third party and your interests, fundamental rights, or freedoms do not override them. Such interests include, in particular, the secure and efficient operation of our website, IT security, prevention of misuse, and handling of general business enquiries. Where storing information on your device or accessing information already stored there requires consent under applicable European or national cookie/ePrivacy law, such storage or access will only take place after your prior consent has been obtained. 3. Retention period As a rule, we retain personal data only for as long as necessary for the specific purpose of the processing. Thereafter, the data is deleted or anonymised unless statutory retention obligations or other legally valid grounds require longer storage. For contractual and payment-related data, commercial and tax retention requirements may require longer storage. Where processing is based on your consent, we process the relevant data until you withdraw that consent, unless another legal basis permits or requires further processing. 4. Hosting via Vercel Our website is provided via the infrastructure of Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. When you access our website, Vercel processes the technical data required to deliver the site and ensure its stability and security. This may include, in particular: • IP address, • date and time of access, • requested page or file, • referrer information, • browser type and version, • operating system and device characteristics, • technical request, network, and protocol data, • information relating to error diagnostics, performance, and system security. The processing is carried out in order to provide our online offering securely, quickly, and reliably. The legal basis is Art. 6(1)(f) GDPR. Where use of our website is directly related to the performance of a contract or pre-contractual measures, Art. 6(1)(b) GDPR may also apply. Vercel processes certain data on our behalf as a processor. Vercel may also process data in the United States and other countries. Vercel is certified under the EU-U.S. Data Privacy Framework and also provides contractual safeguards for international data transfers, in particular the Standard Contractual Clauses. 5. Server log data and IT security When you visit the website, server and security logs are generated for technical reasons. These may contain IP addresses, timestamps, requested resources, HTTP status codes, browser information, and other technical data. We process this data to ensure the operation and security of our website, detect attacks or misuse, and analyse technical errors. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to ensure the secure and uninterrupted operation of our online offering. Log data is deleted or anonymised once it is no longer required for these purposes, unless a security-related investigation or legal obligation requires longer retention. 6. Vercel Web Analytics We use Vercel Web Analytics for statistical analysis of the use of our website. The provider is Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. Vercel Web Analytics enables us to analyse page views and aggregated usage information, such as pages visited, source of access, browser, operating system, device type, and approximate geographic location. This analysis is used to measure reach and to optimise our website technically and editorially. Vercel Web Analytics is designed as a privacy-focused analytics service. Nevertheless, during technical transmission and hosting, data described in the sections “Hosting via Vercel” and “Server log data and IT security” may be processed. Where Vercel Web Analytics is used in a configuration in which no information requiring consent is stored on or read from your device, the processing is based on our legitimate interest in privacy-friendly reach measurement and improving our offering pursuant to Art. 6(1)(f) GDPR. If the specific technical configuration requires consent, the service will only be activated after you have given your consent; in that case, the legal basis is Art. 6(1)(a) GDPR. For any transfers to the USA, the safeguards described in the section “Hosting via Vercel” apply. 7. Google Analytics 4 We use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics helps us understand how visitors use our website. For this purpose, data relating to page views, sessions, interactions, devices used, browsers, operating systems, approximate geographic origin, and technical usage may be processed. In its standard configuration, Google Analytics 4 uses first-party cookies. These include, in particular, cookies such as _ga and _ga_<Container-ID>, which are used to distinguish users and sessions. By default, these cookies may have a lifetime of up to two years, although browser restrictions or our configuration may shorten this period. According to Google, IP addresses are not logged or stored in Google Analytics 4. However, Google may process other technical and usage data and link it with other Google services where this is permitted by the relevant configuration and your consent. Google Analytics is technically integrated from the moment our website is accessed. Where this involves storing or reading analytics cookies or other information on your device that is subject to consent, such processing will only take place after your prior consent has been obtained. Without such consent, Google Analytics may only be used in a technical configuration in which analytics cookies requiring consent are neither set nor read, for example through appropriately configured consent signals or Google Consent Mode. The legal basis for processing that requires consent is Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future via the privacy or cookie settings available on our website. The retention period for user-level and event-level data depends on the retention setting configured in our Google Analytics property. Google Analytics 4 allows, in particular, retention periods of two or fourteen months. Aggregated reports may remain available for longer independently of this. For data relating to European users, Google Ireland Limited is generally the responsible entity in connection with Google Analytics. However, in the course of providing the services, processing may also take place by affiliated companies or service providers outside the European Economic Area. According to Google, the applicable legal transfer mechanisms are used for this purpose, including Standard Contractual Clauses and, where applicable, adequacy mechanisms for certified US companies. We currently do not use Meta Pixel, Google Ads remarketing technologies, or other comparable advertising tracking technologies. If such services are added in the future, we will update this Privacy Policy before they are used. 8. Cookies and similar technologies Our website may use cookies and similar storage technologies. Cookies are small files stored on your device and may contain certain information. We distinguish in particular between: • technically necessary technologies, which are required for operation, security, the checkout process, or storing your privacy preferences, and • optional analytics technologies. These may be technically integrated from the moment the page is accessed; where this involves storing or reading cookies or other information on your device that is subject to consent, this will only occur after you have given your consent. Cookie-less measurement or an equivalent configuration may take place independently of this, provided it is legally permissible under data protection law. To manage your privacy and cookie preferences, we do not use any external cookie or consent management provider. We do not use Matomo. You may change or withdraw any consent you have given at any time with effect for the future via the privacy settings available on the website. You may also delete or block cookies via your browser settings. Disabling technically necessary storage functions may limit the functionality of certain parts of the website. 9. Contact If you contact us via a contact form, email, telephone, or another means, we process the data you provide in order to handle your enquiry. This data may include, in particular: • name, • email address, • telephone number, • content of your message, • information about the property, product, or offer to which your enquiry relates, • any other information you provide voluntarily. If your enquiry relates to a contract or measures prior to entering into a possible contract, processing is carried out on the basis of Art. 6(1)(b) GDPR. For general enquiries, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is to properly manage and document business communications. The data will be deleted once your enquiry has been finally resolved and there are no statutory retention obligations, contractual reasons, or legitimate interests justifying further retention. 10. Contract, booking, order, and checkout data When you make an enquiry, booking, or order through our website, enter into a contract, or use a checkout process, we process the personal data required for this purpose. This data may include, in particular: • first and last name, • billing address and, where applicable, delivery or accommodation address, • email address and telephone number, • information about the selected property, product, or scope of service, • booking, order, and contract data, • billing and transaction data, • payment status and payment references. The processing is carried out in order to take pre-contractual measures and perform the relevant contract on the basis of Art. 6(1)(b) GDPR. Where statutory documentation, accounting, or tax obligations apply, subsequent processing is carried out on the basis of Art. 6(1)(c) GDPR. We use the booking system Beds24 as a processor to manage bookings, availability, and the related guest communication; the data required for the booking is stored there. 11. Payment processing via Stripe We use Stripe for payment processing. For users and business customers in the European Economic Area, Stripe services are provided in particular by Stripe group companies in Ireland, including Stripe Payments Europe, Limited and Stripe Technology Europe, Limited. When you use Stripe as a payment method or a payment is processed through Stripe’s infrastructure, the data necessary for the transaction is transmitted to Stripe. This may include, in particular: • name and contact details, • billing address, • payment information, • transaction amount and currency, • date, time, and status of the transaction, • technical data such as IP address and device information, • information necessary for fraud and misuse prevention. The transfer is carried out in order to perform the contract and process the payment requested by you on the basis of Art. 6(1)(b) GDPR. Where data is processed to comply with legal obligations, Art. 6(1)(c) GDPR may also apply. Stripe also processes certain data under its own responsibility under data protection law, in particular for payment processing, fraud prevention, security, and compliance with regulatory obligations. Stripe may share data within the Stripe group as well as with service providers and subprocessors, and may also process data outside the European Economic Area. According to Stripe, international data transfers are based, among other mechanisms, on the EU-U.S. Data Privacy Framework and the European Commission’s Standard Contractual Clauses. As a rule, we only receive the information necessary to confirm, allocate, and manage the payment. Where technical payment processing is handled directly through Stripe, we do not ourselves store full credit card details or complete bank account information. 12. Payment processing via PayPal If you select PayPal as a payment option, payment processing will be carried out via PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. For payment processing, the following data in particular may be transmitted to PayPal: • name and contact details, • billing or delivery information, • transaction amount and currency, • information about the order or booking, • payment status, • technical and security-relevant information. The data transfer is carried out in order to perform the contract and process the payment method selected by you on the basis of Art. 6(1)(b) GDPR. PayPal processes certain data under its own responsibility, for example for payment processing, identity verification, fraud prevention, risk assessment, and compliance with legal obligations. PayPal operates internationally. Personal data may therefore also be processed outside the European Economic Area. According to PayPal, internal group data protection rules and other legally provided safeguards for international data transfers are used for this purpose. 13. Recipients of personal data and processors We only disclose personal data where this is necessary to perform a contract, provide our website, process payments, comply with legal obligations, or on the basis of another permissible legal ground. Recipients or categories of recipients may include, in particular: • hosting and IT service providers, • analytics providers within the scope of your consent or a permissible privacy-friendly configuration, • payment service providers, • booking and channel management systems (Beds24), • banks and financial service providers, • tax advisers, legal advisers, and auditors, • authorities or courts where there is a legal obligation. Where service providers process personal data exclusively on our behalf, we enter into the legally required data processing agreements with them. 14. Transfers of data to third countries Some of the service providers we use are based in the United States or process data via internationally distributed technical infrastructure. As a result, personal data may be transferred to countries outside the European Economic Area. Such transfers only take place where the applicable legal requirements are met. Depending on the provider, the transfer may be based, in particular, on an adequacy decision by the European Commission, certification under the EU-U.S. Data Privacy Framework, the European Commission’s Standard Contractual Clauses, Binding Corporate Rules, or another legally recognised transfer mechanism. 15. SSL/TLS encryption For security reasons, our website uses SSL or TLS encryption. This protects data transmitted between your browser and our website against unauthorised access by third parties. You can usually recognise an encrypted connection by the use of “https://” in your browser’s address bar. 16. Your rights Under the GDPR, and provided the relevant legal requirements are met, you have in particular the following rights: • Right of access to the personal data we process about you, pursuant to Art. 15 GDPR, • Right to rectification of inaccurate or incomplete data, pursuant to Art. 16 GDPR, • Right to erasure of your personal data, pursuant to Art. 17 GDPR, • Right to restriction of processing, pursuant to Art. 18 GDPR, • Right to data portability, pursuant to Art. 20 GDPR, • Right to object to certain processing activities, pursuant to Art. 21 GDPR, • Right to withdraw consent pursuant to Art. 7(3) GDPR, with effect for the future. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal. To exercise your rights, you may contact us at: Predator SLU Email: info@predatorsl.com We may request appropriate proof of your identity where necessary to ensure that personal data is not disclosed or modified without authorisation by third parties. 17. Objection to processing based on legitimate interests Where we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right under Art. 21 GDPR to object to such processing at any time on grounds relating to your particular situation. In that case, we will no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or unless the processing is necessary for the establishment, exercise, or defence of legal claims. 18. Right to lodge a complaint with a supervisory authority You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes applicable data protection law. As Predator SLU is established in Spain, you may in particular contact the Spanish Data Protection Agency (Agencia Española de Protección de Datos – AEPD). Independently of this, the GDPR may also entitle you to lodge a complaint with the competent supervisory authority at your place of residence or place of work. 19. Data security We implement appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, unauthorised disclosure, or alteration. The security measures used are reviewed and adapted in line with technological developments and the relevant risk. Despite all security measures, no transmission of data over the Internet can be completely protected against all risks. 20. Statutory guest registration (SES.Hospedajes) As an accommodation provider in Spain, we are legally required to record certain data of all travellers – including minors – and to transmit it to the Spanish Ministry of the Interior (SES.Hospedajes registration system, Real Decreto 933/2021). The data is collected via our online check-in or on site. For this purpose we process, in particular: • first and last names, • gender and date of birth, • nationality, • type and number of the identity document (for persons aged 14 or over) and, where applicable, the número de soporte, • home address, • contact details (telephone and/or email), • for minors, the relationship to the accompanying responsible adult, • a handwritten signature (for persons aged 14 or over), • booking details (accommodation, arrival and departure dates, number of guests). The legal basis is Art. 6(1)(c) GDPR (legal obligation) in conjunction with Real Decreto 933/2021. The recipient of the report is the Spanish Ministry of the Interior (SES.Hospedajes). In accordance with the statutory requirement, the registration data is retained for three years and then deleted. Identity document numbers and signatures are stored in encrypted form in our systems. If you pay the Balearic tourist tax (ITS) online via our guest portal, the payment is processed via Stripe (see the section “Payment processing via Stripe”). 21. Changes to this Privacy Policy We may amend this Privacy Policy if our website, the services we use, or legal requirements change. The version published on this website at the relevant time will apply. In particular, we will update this Privacy Policy before using any new analytics, advertising, tracking, or payment services.
Privacy Policy | Portixol Holidays